Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35094

Опубликовано: 01 апр. 2026
Источник: nvd
CVSS3: 3.3
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:freedesktop:libinput:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:43:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:44:*:*:*:*:*:*:*

EPSS

Процентиль: 4%
0.00146
Низкий

3.3 Low

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-825

Связанные уязвимости

CVSS3: 3.3
ubuntu
4 месяца назад

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.

CVSS3: 3.3
redhat
4 месяца назад

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.

CVSS3: 3.3
debian
4 месяца назад

A flaw was found in libinput. An attacker capable of deploying a Lua p ...

CVSS3: 3.3
github
4 месяца назад

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.

EPSS

Процентиль: 4%
0.00146
Низкий

3.3 Low

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-825